Vulnerability  ·  2026-08-01

Strands Agents Tools — Credential Exfiltration via LLM-Steerable http_request Proxy Routing

VulnerabilityHigh impactGlobalCVE-2026-18394
AWS published a security bulletin and NVD listed CVE-2026-18394 (CVSS 7.4, High) on 2026-07-31, describing how prompt injection can manipulate an agent into routing HTTP requests through attacker-controlled proxies, leaking configured credentials.
This is a direct demonstration of prompt injection escalating to credential theft in a production-grade agent SDK backed by AWS — showing that tool-level credential configuration in agent frameworks needs the same scrutiny as any other secret-handling code path, since the LLM itself is an attacker-influenceable decision point.
Incorrect authorization in the http_request tool allows a remote attacker — via prompt injection influencing the LLM's tool-calling decisions — to redirect outbound requests through actor-controlled proxy infrastructure, causing credentials configured via HTTP_REQUEST_TOKEN_CONFIG to be sent to the attacker's proxy and exfiltrated.
Strands Agents Tools (strands-agents-tools) before 0.8.2
Upgrade to strands-agents-tools 0.8.2+; see AWS Security Bulletin 2026-069-aws for remediation guidance.
AWS Security Bulletin 2026-069NVD CVE-2026-18394
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →